Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
77,020cataloged exploits
35,276CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,446Referência 22,166GitHub PoC 14,080VulnCheck XDB 8,604Nuclei 4,251Metasploit 3,473✓ verified onlyrecentpopularrisk
22,166 exploits
Referência✓ VexDay Proof
Mole Group Taxi Calc Dist Script - Authentication Bypass
SQL injection vulnerability in login.php in Mole Group Taxi Map Script (aka Taxi Calc Dist Script) allows remote attacke
23RISK
open ↗Referência✓ VexDay Proof
Quake 3 Engine Client - 'CG_ServerCommand()' Remote Overflow
Stack-based buffer overflow in the CG_ServerCommand function in Quake 3 Engine as used by Soldier of Fortune 2 (SOF2MP)
23RISK
open ↗Referência✓ VexDay Proof
SoftComplex PHP Image Gallery - 'ctg' SQL Injection
SQL injection vulnerability in index.php in SoftComplex PHP Image Gallery allows remote attackers to execute arbitrary S
23RISK
open ↗Referência✓ VexDay Proof
DigiAffiliate 1.4 - Authentication Bypass
Multiple SQL injection vulnerabilities in login.asp in Digiappz DigiAffiliate 1.4 and earlier allow remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
Shader TV (Beta) - Multiple SQL Injections
Multiple SQL injection vulnerabilities in Shader TV (Beta) allow remote authenticated administrators to execute arbitrar
23RISK
open ↗Referência
CVE-2014-6242
Multiple SQL injection vulnerabilities in the All In One WP Security & Firewall plugin before 3.8.3 for WordPress allow
23RISK
open ↗Referência✓ VexDay Proof
FluentCMS - 'view.php' SQL Injection
SQL injection vulnerability in view.php in DotContent FluentCMS 4.x allows remote attackers to execute arbitrary SQL com
23RISK
open ↗Referência
CVE-2014-6271
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open ↗Referência✓ VexDay Proof
OneCMS 2.5 - Blind SQL Injection
SQL injection vulnerability in asd.php in OneCMS 2.5 allows remote attackers to execute arbitrary SQL commands via the s
23RISK
open ↗Referência
CVE-2014-6271
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open ↗Referência
CVE-2009-4560
SQL injection vulnerability in profile.php in WebLeague 2.2.0 allows remote attackers to execute arbitrary SQL commands
23RISK
open ↗Referência✓ VexDay Proof
Simple Machines Forum (SMF) 1.1.6 - Code Execution
Cross-site request forgery (CSRF) vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 be
23RISK
open ↗Referência
CVE-2014-6271
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISK
open ↗Referência✓ VexDay Proof
Apartment Search Script - Arbitrary File Upload / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in listtest.php in Apartment Search Script allows remote attackers to inject ar
23RISK
open ↗Referência✓ VexDay Proof
Pre ADS Portal 2.0 - Authentication Bypass / Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Pre ADS Portal 2.0 and earlier allow remote attackers to inject a
23RISK
open ↗Referência✓ VexDay Proof
Pre ADS Portal 2.0 - Authentication Bypass / Cross-Site Scripting
homeadmin/adminhome.php in Pre ADS Portal 2.0 and earlier does not require administrative authentication, which allows r
23RISK
open ↗Referência
CVE-2009-4561
Multiple SQL injection vulnerabilities in Admin/index.php in WebLeague 2.2.0, when magic_quotes_gpc is disabled, allow r
23RISK
open ↗Referência✓ VexDay Proof
U&M Software Signup 1.1 - Authentication Bypass
U&M Software Signup 1.0 and 1.1 does not require administrative authentication for all scripts in the admin/ directory,
23RISK
open ↗Referência✓ VexDay Proof
U&M Software Event Lister 1.0 - Authentication Bypass
U&M Software Event Lister (aka JustListIt) 1.0 does not require administrative authentication for all scripts in the adm
23RISK
open ↗Referência✓ VexDay Proof
DELTAScripts PHP Links 1.3 - Authentication Bypass
SQL injection vulnerability in admin/adm_login.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to
23RISK
open ↗Referência✓ VexDay Proof
AJ Article 1.0 - Authentication Bypass
SQL injection vulnerability in index.php in AJ Square AJ Article allows remote attackers to execute arbitrary SQL comman
23RISK
open ↗Referência✓ VexDay Proof
CMScout 2.06 - SQL Injection / Local File Inclusion
Multiple SQL injection vulnerabilities in CMScout 2.06 allow remote authenticated users to execute arbitrary SQL command
23RISK
open ↗Referência✓ VexDay Proof
CMScout 2.06 - SQL Injection / Local File Inclusion
Multiple directory traversal vulnerabilities in CMScout 2.06, when register_globals is enabled, allow remote attackers t
23RISK
open ↗Referência✓ VexDay Proof
PHPmotion 2.1 - Cross-Site Request Forgery
Multiple cross-site request forgery (CSRF) vulnerabilities in password.php in PHPmotion 2.1 and earlier allow remote att
23RISK
open ↗Referência✓ VexDay Proof
Flexphplink Pro - Arbitrary File Upload
Unrestricted file upload vulnerability in submitlink.php in FlexPHPLink Pro 0.0.7 allows remote attackers to execute arb
23RISK
open ↗Referência✓ VexDay Proof
Keller Web Admin CMS 0.94 Pro - Local File Inclusion (2)
Directory traversal vulnerability in Public/index.php in Keller Web Admin CMS 0.94 Pro allows remote attackers to includ
23RISK
open ↗Referência✓ VexDay Proof
Simple Machines Forum (SMF) 1.1.4 - SQL Injection
SQL injection vulnerability in Load.php in Simple Machines Forum (SMF) 1.1.4 and earlier allows remote attackers to exec
23RISK
open ↗Referência✓ VexDay Proof
RSMScript 1.21 - Cross-Site Scripting / Insecure Cookie Handling
RSMScript 1.21 allows remote attackers to bypass authentication and gain administrative privileges by setting the verifi
23RISK
open ↗Referência✓ VexDay Proof
BlogPHP 2.0 - Privilege Escalation / SQL Injection
index.php in BlogPHP 2.0 allows remote attackers to gain administrator privileges via a crafted email parameter in a reg
23RISK
open ↗Referência
CVE-2009-4569
SQL injection vulnerability in elkagroup Image Gallery allows remote attackers to execute arbitrary SQL commands via the
23RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.